CVE-2023-35378
Windows Projected File System Elevation of Privilege Vulnerability
CVSS
7.0
High
EPSS
0.4%
p28
KEV
—
Exploit Today
9
0-100
Published: Aug 8, 2023 · Last modified: Aug 10, 2026 · CWE-367 · CWE-362
0.4%EPSS · 30 days0.4%
2026-08-182026-09-15
Windows Projected File System Elevation of Privilege Vulnerability
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-734635.3 MED—
———On affected platforms running Arista EOS, when multiple gRPC Network Security Interface (gNSI) transports are configured, a race condition in the gNSI Authz service may cause a policy rotation to fail silently. An authenticated user whose access was revoked by the new policy may retain unauthorized access to gRPC interfaces. This does not affect Bootz.
This issue was discovered internally by Arista, and the company is not aware of any malicious exploitation of this vulnerability in customer networks.2hCVE-2024-112226.4 MED—
———GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed a developer user to perform actions in the context of another user's merge request commit due to a race condition issue in pipeline creation.5hCVE-2026-917488.3 HIG—
———Race condition in Extensions in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to potentially execute arbitrary code outside the sandbox via UI Interaction. (Chromium security severity: High)21hCVE-2026-917445.3 MED—
———Race condition in PlatformIntegration in Google Chrome on on Mac prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to obtain sensitive information via a crafted HTML page. (Chromium security severity: High)21hCVE-2026-917438.3 HIG—
———Race condition in Core in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)21hCVE-2026-91723——
———Race condition in WebAppInstalls in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)1d